A global manufacturing company needs to manage access to highly confidential design documents stored in SharePoint Online and OneDrive. They want to ensure that only users from specific departments can access these documents, even if they are shared externally, and that access is revoked if a user leaves those departments. Furthermore, they need to apply specific visual markings and encryption. Which combination of Microsoft Purview features should be utilized?
- AAzure AD Conditional Access policies requiring specific device compliance, combined with Sensitivity labels for encryption only.
- BSensitivity labels configured with encryption and visual markings, combined with Data Loss Prevention (DLP) policies to prevent unauthorized sharing.
- CInformation Barriers (IB) to segment user groups, combined with SharePoint site permissions and custom external sharing settings.
- DSensitivity labels with encryption and visual markings, published to users, and configured for 'container management' on SharePoint sites and OneDrive accounts.
Show answer & explanationAnswer & explanation
Correct answer: D. Sensitivity labels with encryption and visual markings, published to users, and configured for 'container management' on SharePoint sites and OneDrive accounts.
Sensitivity labels with container management (for SharePoint sites and OneDrive accounts) allow for controlling access to the container itself based on the label. This means only users with appropriate permissions (granted via the label) can access the content within, and access is dynamic. Combined with encryption and visual markings, this comprehensive approach meets all requirements, including external sharing controls and dynamic access based on user attributes.
Why the other options are wrong
- A. Conditional Access focuses on access conditions (device, location) at the time of login, not dynamic content access control based on user department membership within the document's lifecycle or applying visual markings.
- B. While Sensitivity labels with encryption and visual markings are good, DLP primarily prevents sharing, it doesn't dynamically control access to the container based on user attributes or enforce access if a user leaves a department.
- C. Information Barriers segment communications, not directly manage access to documents in SharePoint/OneDrive based on dynamic department membership for external sharing scenarios. SharePoint permissions are static and harder to manage dynamically at scale.
Sensitivity Labels with Container Management
Sensitivity labels can be applied to containers (SharePoint sites, OneDrive accounts, Teams) to enforce access controls, visual markings, and encryption for all content within, dynamically adjusting based on user attributes.
- Extends sensitivity labels beyond individual files to entire containers.
- Controls site access, external sharing, and guest access based on label.
- Dynamically enforces policies, including access revocation if user attributes change.
Memory trick: Labels on containers lock down contents and control who gets in.